The Solar Winds Attack: The Cozy Bear, a hackers’ group, and a hacking unit — an example from the Microsoft Security Development Lifecycle
The attack took place just days after Microsoft announced that it was going to tighten up its software security. While Microsoft customers don’t appear to have been impacted in this new incident and this wasn’t the result of a Microsoft vulnerability, this is still the latest in a line of cybersecurity incidents for Microsoft. It found itself at the center of the SolarWinds attack nearly three years ago, then 30,000 organizations’ email servers were hacked in 2021 due to a Microsoft Exchange Server flaw, and Chinese hackers breached US government emails via a Microsoft cloud exploit last year.
Microsoft is now changing the way it designs, builds, tests, and operates its software and services. The biggest change to the security approach has been announced by the company since it introduced its Security Development Lifecycle in 2004.
Intelligence-gathering is the main focus of the SVR. It primarily targets governments, diplomats, think tanks and IT service providers in the U.S. and Europe.
Microsoft calls the unit a hacking unit. Prior to revamping its threat-actor nomenclature last year, it called the group Nobelium. The group that’s owned by Mandiant is called Cozy Bear.
Comments on a Google-Cryptanalysis of an X-ray Scanning Threat by a Microsoft Threat-Insight Team
A month ago a new Securities and Exchange Commission rule took effect, requiring publicly traded companies to tell when they have been involved in any kind of data breeches that could hurt their business. It gives them four days to do so unless they obtain a national-security waiver.
In Friday’s SEC regulatory filing, Microsoft said that “as of the date of this filing, the incident has not had a material impact” on its operations. The incident was not determined as to whether it was likely to impact its finances.
The threat actor tries to log into multiple accounts using the same password. In an August blog post, Microsoft described how its threat-intelligence team discovered that the same Russian hacking team had used the technique to try to steal credentials from at least 40 different global organizations through Microsoft Teams chats.




